Documentation template
EU AI Act Documentation Template
Use this starter structure to create a practical AI system file. It is useful for internal reviews, customer security questionnaires, investor diligence, and early preparation for higher-risk workflows.
Disclaimer: This template is not legal advice and is not a complete conformity assessment package. High-risk systems may require additional technical documentation, quality management, testing, monitoring, and specialist review.
Copyable system file outline
| Section | What to include |
|---|---|
| 1. System identity | Product name, feature name, owner, version, release date, markets, and review date. |
| 2. Intended purpose | The task the AI is designed to perform, target users, affected people, and excluded uses. |
| 3. Role and supply chain | Your role as provider, deployer, importer, distributor, or downstream integrator, plus model and vendor dependencies. |
| 4. System description | Architecture, model family, data flow, inputs, outputs, integrations, prompts, retrieval sources, and user controls. |
| 5. Risk classification | Prohibited-practice screen, high-risk screen, Annex III review, transparency obligations, and the reason for the chosen classification. |
| 6. Data and evaluation | Data categories, data quality checks, evaluation methods, representative test cases, known gaps, and bias review where relevant. |
| 7. Risk controls | Mitigations, guardrails, access controls, red-team findings, misuse cases, and residual risks. |
| 8. Human oversight | Who reviews outputs, when escalation is required, how overrides work, and what users are told. |
| 9. Logging and monitoring | Events logged, retention approach, issue review cadence, incident response, model-change review, and customer feedback channel. |
| 10. Instructions and notices | User instructions, limitations, AI transparency notice, support contacts, and customer admin guidance. |
| 11. Change history | Model changes, prompt changes, data-source changes, new markets, new customer use cases, and reviewer sign-off. |
Minimum memo for lower-risk features
- One paragraph describing the feature and intended purpose.
- A classification table covering prohibited, high-risk, limited transparency, and minimal-risk signals.
- A copy of the user-facing AI notice, if one is used.
- A dated owner sign-off and next review date.
High-risk evidence add-ons
- Risk management plan and testing evidence.
- Technical logs and record-keeping approach.
- Human oversight design and reviewer instructions.
- Accuracy, robustness, and cybersecurity notes.
- Post-market monitoring and incident workflow.
Official sources
Last reviewed: July 3, 2026.